Executive Summary
In June 2024, SonicWall disclosed a significant data breach impacting all users of its cloud backup service. Attackers successfully gained unauthorized access and exfiltrated firewall configuration files belonging to these customers. The breach, which reportedly occurred in late May 2024, does not appear to have affected the core SonicWall services but poses considerable risk because leaked configurations may contain sensitive network information, VPN details, hashed passwords, and other operational data. SonicWall took immediate action by disabling the impacted service and advising affected clients to reset credentials and review their setups.
This breach highlights increasing attacker focus on cloud-managed infrastructure, particularly targeting device configurations that can offer deep intelligence on enterprise environments. With threat actors exploiting misconfigurations and weak controls in supply chain and managed services, regulators and CISOs are under pressure to strengthen both preventative and responsive security postures.
Why This Matters Now
Widespread theft of firewall configurations directly threatens enterprise network integrity and exposes potential vectors for sophisticated follow-on attacks, including lateral movement and espionage. As more organizations migrate critical infrastructure to cloud platforms, proactive security measures and rapid incident response are crucial to mitigate escalating risks from similar supply chain attacks.
Attack Path Analysis
The attacker gained an initial foothold by exploiting a vulnerability or misconfiguration in SonicWall's cloud backup service. After access, they escalated their privileges to obtain broader control within the environment. The adversary moved laterally to access firewall configuration data across multiple customer environments. Command and control was maintained via covert outbound communication. The stolen firewall configurations were exfiltrated, likely leveraging unmonitored or insufficiently restricted egress channels. The impact was a large-scale data breach affecting all customers using the cloud backup service, potentially exposing sensitive configurations and undermining network defenses.
Kill Chain Progression
Initial Compromise
Description
Attacker exploited a vulnerable or misconfigured interface in the SonicWall cloud backup service to gain initial access.
Related CVEs
CVE-2024-40766
CVSS 9.6An improper access control vulnerability in SonicWall SonicOS allows unauthenticated remote attackers to gain unauthorized access, leading to potential firewall crashes.
Affected Products:
SonicWall SonicOS – Gen 5, Gen 6, Gen 7 (<= 7.0.1-5035)
Exploit Status:
exploited in the wildCVE-2025-40601
CVSS 7.5A stack-based buffer overflow vulnerability in SonicWall SonicOS SSLVPN service allows unauthenticated remote attackers to perform Denial of Service (DoS) attacks, potentially crashing the firewall.
Affected Products:
SonicWall SonicOS – Gen 7, Gen 8
Exploit Status:
no public exploit
MITRE ATT&CK® Techniques
Valid Accounts
Data from Cloud Storage
Exfiltration Over C2 Channel
Data Manipulation: Stored Data Manipulation
Modify Authentication Process
Account Discovery
Brute Force
Potential Compliance Exposure
Mapping incident impact across multiple compliance frameworks.
PCI DSS 4.0 – Implement automated audit trails for all system components
Control ID: 10.2.1
NYDFS 23 NYCRR 500 – Cybersecurity Policy
Control ID: 500.03
DORA – ICT Risk Management Requirements
Control ID: Article 10
CISA Zero Trust Maturity Model 2.0 – Data Access Monitoring
Control ID: Data Pillar: Visibility & Analytics
NIS2 Directive – Incident Handling & Business Continuity
Control ID: Article 21(2)d
Sector Implications
Industry-specific impact of the vulnerabilities, including operational, regulatory, and cloud security risks.
Computer/Network Security
SonicWall firewall configuration theft exposes security providers to supply chain attacks, compromising their ability to protect client networks and infrastructure.
Financial Services
Stolen firewall configurations threaten PCI compliance and expose banking systems to lateral movement attacks, compromising encrypted transaction data protection.
Health Care / Life Sciences
Breach compromises HIPAA compliance requirements for encrypted traffic and network segmentation, exposing patient data to unauthorized access and exfiltration.
Government Administration
Configuration theft enables threat actors like Salt Typhoon to bypass zero trust controls and perform reconnaissance on critical government infrastructure.
Sources
- SonicWall: Firewall configs stolen for all cloud backup customershttps://www.bleepingcomputer.com/news/security/sonicwall-firewall-configs-stolen-for-all-cloud-backup-customers/Verified
- SonicWall Releases Advisory for Customers after Security Incidenthttps://www.cisa.gov/news-events/alerts/2025/09/22/sonicwall-releases-advisory-customers-after-security-incidentVerified
- SonicWall confirms all of its cloud backup customers were affected by data breachhttps://www.techradar.com/pro/security/sonicwall-confirms-every-cloud-backup-customer-was-hit-by-data-breachVerified
- SonicWall blames state-backed hackers for breachhttps://cybernews.com/security/sonicwall-breach-state-sponsored-hackers/Verified
Frequently Asked Questions
Cloud Native Security Fabric Mitigations and ControlsCNSF
Zero Trust segmentation, east-west traffic controls, egress policy enforcement, and centralized visibility would have drastically limited adversary movement, detected abnormal access, and prevented or constrained exfiltration of sensitive configurations.
Control: Cloud Native Security Fabric (CNSF)
Mitigation: Inline inspection and policy enforcement could have detected or blocked suspicious initial access attempts.
Control: Zero Trust Segmentation
Mitigation: Least privilege and microsegmentation would have constrained escalation and limited attacker reach even after initial access.
Control: East-West Traffic Security
Mitigation: Internal movement would be monitored and restricted, raising alerts for anomalous cross-tenant activity.
Control: Threat Detection & Anomaly Response
Mitigation: Anomalous C2 patterns would be detected and trigger alerts for incident response.
Control: Egress Security & Policy Enforcement
Mitigation: Policy-based filtering could prevent or alert on unauthorized data egress from critical backup storage.
Centralized observability enables timely detection, forensics, and rapid response to contain business impact.
Impact at a Glance
Affected Business Functions
- Network Security Management
- Remote Access Services
- Firewall Configuration Management
Estimated downtime: 7 days
Estimated loss: $5,000,000
The breach exposed encrypted firewall configuration backup files, including network rules, VPN settings, and administrative credentials. While the credentials were encrypted, possession of these files could increase the risk of targeted attacks.
Recommended Actions
Key Takeaways & Next Steps
- • Deploy Zero Trust Segmentation and microsegmentation to isolate cloud backup infrastructure from other resources.
- • Enforce strong egress security policies and FQDN filtering to block unauthorized outbound data transfers.
- • Implement inline anomaly detection and baselining to rapidly surface suspicious access or data movement within backup systems.
- • Continuously monitor and audit backup system access using centralized multicloud visibility tools.
- • Regularly validate encryption of sensitive data in transit and ensure encrypted private circuits for all backup-related flows.



